bootcamp
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
run.shscript is vulnerable to command injection through its session resumption logic. Thecmd_resumefunction reads therolevalue from the local state file (~/.embry/bootcamp_state.json) usinggrepandsedwithout performing any validation on the extracted string. This value is then passed to thesave_statefunction, which interpolates it into an unquoted heredoc (cat > ... <<EOJSON). If the state file is modified (e.g., by another process or manual edit) to contain a command substitution payload such as"role": "$(id)", the command will be executed by the shell whensave_stateis called during the resumption process. - [SAFE]: The
startcommand implementation correctly validates the--roleargument against a strict whitelist ('operator', 'compliance-officer', 'developer') before processing, preventing direct injection via initial command-line arguments. - [SAFE]: The skill follows secure patterns for cross-skill execution by deriving the
SKILLS_DIRpath relative to the script's own directory and explicitly unsettingVIRTUAL_ENVto avoid environment conflicts during subprocess calls. - [SAFE]: No external network dependencies or remote code downloads were detected; all operations are performed using local shell scripts and internal system tools.
Audit Metadata